Last updated July 25, 2026. This page explains what we collect when you use Dr. Security and why.
When you request a free scan, we collect the URL you submit, the email address you provide to receive your report, and basic technical metadata about the request (timestamp, referring page, UTM parameters). If you create an account, we also store your account details and scan history.
Findings evidence (such as an exposed key or header value) is redacted before it's stored or shown in a report. We keep enough of the original value to prove the finding is real, and no more. We don't resell or share scan evidence with anyone outside your report.
We use your email to deliver your scan report and, if you opt in, occasional related updates. We use aggregated, anonymized scan data to improve our checks. We don't sell personal information to third parties.
We use minimal, privacy-respecting analytics to understand which pages and features are used, so we know what to improve. We don't use third-party advertising trackers.
We keep scan requests and reports for as long as your account is active, or for a reasonable period after a one-time free scan so you can retrieve your report. You can ask us to delete your data at any time.
You can request a copy of the data we hold about you, ask us to correct it, or ask us to delete it, subject to what we're required to keep for legal or security reasons. Contact [email protected] to make a request.
We'll update this page if our practices change and note the date above. Material changes will be communicated by email where we have one on file.
Questions about this policy? Email [email protected].